US2005125195A1PendingUtilityA1

Method, apparatus and sofware for network traffic management

Priority: Dec 21, 2001Filed: Dec 23, 2002Published: Jun 9, 2005
Est. expiryDec 21, 2021(expired)· nominal 20-yr term from priority
Inventors:Juergen Brendel
H04L 63/1408H04L 43/026H04L 43/00H04L 43/16H04L 63/1458H04L 63/1425H04L 43/106
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A network traffic evaluation device is provided that may be used to warn of or prevent trafficabnormalities such as denial of service attacks. The device includes a data interface to receive one or both of network traffic and data indicative of characteristics f network traffic. The network traffic and/or data received by the data interface is processed for predeterminedcharacteristics that indicate that the network traffic contains a subset of attack traffic. Upon detection of the predetermined characteristics information defining a superset is provided. The superset is a portion of the network traffic that contains the subset and defines network traffic that may be redirected and/or blocked by a network device.

Claims

exact text as granted — not AI-modified
1 . A traffic evaluation device including a data interface to receive one or both of network traffic and data indicative of characteristics of network traffic and including processing means operable to evaluate the network traffic and/or data received by said data interface for predetermined characteristics that indicate that the network traffic contains a subset of attack traffic, and upon detection of said predetermined characteristics retrieve from memory information defining a superset and provide an output defining said superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by a network device.  
   
   
       2 . The traffic evaluation device of  claim 1 , wherein said output is in communication with the network device.  
   
   
       3 . The traffic evaluation device of  claim 1  wherein said data interface is adapted to receive data from a plurality of network devices.  
   
   
       4 . The traffic evaluation device of  claim 3  wherein and the processing means provides an output in communication with each network device capable of communicating a superset for the network device.  
   
   
       5 . The traffic evaluation device of  claim 4  wherein the operation of said processing means to evaluate data received by said data interface for the presence of predetermined characteristics in said network traffic includes considering data from two or more network devices together.  
   
   
       6 . The traffic evaluation device of  claim 1  wherein said data interface is further operable to receive network traffic from said network device, and dependent on any predetermined characteristics detected apply one or more filters to said network traffic to create filtered traffic and output said filtered traffic.  
   
   
       7 . The traffic evaluation device of  claim 1  wherein said data interface is adapted to receive data from at least a first network device and a second network device and the processing means is operable to retrieve information defining the capabilities of said first and second network devices and if a smaller superset can be achieved by the second network device on data received by the first network device, provide on its output to the first network device instructions that cause it to forward traffic received by it to a second network device and instruct the second network device to redirect and/or block and/or filter the network traffic received from the first network device that is defined by the superset.  
   
   
       8 . The traffic evaluation device of  claim 1  wherein the processing means is further operable to identify and assemble together packet fragments into a single packet and evaluate the assembled packet against said predetermined characteristics.  
   
   
       9 . The traffic evaluation device of  claim 1 , wherein the predetermined characteristics include the existence of network traffic having predefined ratios of packets.  
   
   
       10 . The traffic evaluation device of  claim 1  wherein the predetermined characteristics include a deviation between one or more current traffic parameters and one or more normal traffic parameters.  
   
   
       11 . The traffic evaluation device of  claim 1 , wherein the processing means is operable to identify groups of data in said network traffic and evaluate each said group for said predetermined characteristics, wherein the predetermined characteristics used are dependent on the group.  
   
   
       12 . The traffic evaluation device of  claim 9 , wherein the processing means is operable to identify groups of data in said network traffic and evaluate each said group for said predefined ratios, wherein the predefined ratios used are dependent on the group.  
   
   
       13 . A traffic evaluation device including a data interface to receive from a network device one or both of network traffic and data indicative of characteristics of network traffic and including processing means operable to separate the network traffic and/or data indicative of characteristics of network traffic received by said network interface into a plurality of groups and evaluate each group for predetermined characteristics that indicate that the group contains a subset of attack traffic.  
   
   
       14 . The traffic evaluation device of  claim 13 , wherein upon detection of said predetermined characteristics, the processing means is further operable to retrieve from memory information defining a superset and provide an output defining said superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by a network device.  
   
   
       15 . Apparatus for monitoring network traffic for a traffic profile abnormality, the apparatus including data volume observing means for observing the volume of data communicated to or within a network and data classification means for classifying data communicated to or within the network into one or more of a plurality of classes and a processing means operable to: 
 a) for at least one pair of classes compute a ratio of: 
 observed data volume of one class or a function of observed data volume of one or more classes to  
 observed data volume of another class or a function of observed data volume of one or more other classes;  
   b) evaluate whether the one or more ratios indicate abnormal network traffic against predetermined criteria and if so output either or both of a signal indicating the potential occurrence of an attack.    
   
   
       16 . Apparatus as claimed in  claim 15  wherein the processing means provide instructions to a network device to take predetermined action in response to an attack.  
   
   
       17 . Apparatus as claimed in  claim 15  wherein the traffic profile abnormality includes a denial of service attack.  
   
   
       18 . The apparatus of  claim 15 , wherein the processing means is further operable to compute at least one degree of abnormality, the or each degree of abnormality being a weighted function of one or more ratios and wherein each degree of abnormality is one of the one or more ratios that is evaluated in step b).  
   
   
       19 . The apparatus of  claim 15 , wherein the processing means is further operable to upon detection of an attack retrieve from memory information defining a set of data that contains the attack traffic and provide an output defining said set defines network traffic that may be redirected and/or blocked by a network device.  
   
   
       20 . The apparatus of  claim 15  wherein the processing means is further operable to identify and assemble together packet fragments into a single packet and evaluate the assembled packet against said predetermined criteria.  
   
   
       21 . A method of network traffic management including using a computer processing means to evaluate network traffic for predetermined characteristics that indicate that the network traffic contains a subset of attack traffic and upon detection of said predetermined characteristics retrieving from memory a superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by a network device and communicating said superset to the network device.  
   
   
       22 . The method of  claim 21  including evaluating for predetermined characteristics network traffic from two or more network devices together.  
   
   
       23 . The method of  claim 21  wherein upon detection of said predetermined characteristics the method further includes directing said network device to redirect certain traffic to the computer processing means, and using the computer processing means to apply one or more filters to said network traffic to create filtered traffic and return said filtered traffic to the network device.  
   
   
       24 . The method of  claim 21  wherein the predetermined conditions include the existence of network traffic having predefined ratios of packets.  
   
   
       25 . The method of  claim 21  further including using the processing means to identify groups of data in said network traffic and evaluating each said group for said predetermined characteristics, wherein the predetermined characteristics used are dependent on the group.  
   
   
       26 . The method of  claim 24  further including using the processing means to identify groups of data in said network traffic and evaluate each said group for said predefined ratios and wherein the predefined ratios used are dependent on the group.  
   
   
       27 . A method of managing network traffic including using a processing means to separate network traffic received by a network device or data indicating characteristics of network traffic received by a network device of into a plurality of groups and evaluating each group for predetermined characteristics that indicate that the group contains a subset of attack traffic and upon detection of said predetermined characteristics, retrieving from a memory information defining a superset and communicating to a network device that receives the network traffic an output defining said superset, wherein the superset is a portion of the network traffic that contains said subset and defines network traffic that may be redirected and/or blocked by the network device.  
   
   
       28 . A method of monitoring network communication for a network traffic abnormality, the method including 
 a) observing the volume of data communicated to or within a network;    b) classifying data communicated to or within the network into one or more of a plurality of classes;    c) using a computer processing means, compute for at least one pair of classes a ratio of: 
 observed data volume of one class or a function of observed data volume of one or more classes to  
 observed data volume of another class or a function of observed data volume of one or more other classes;  
   d) evaluate whether the one or more ratios indicate abnormal network traffic against predetermined criteria and if so output either or both of a signal indicating the potential occurrence of an abnormality or instructions to a network device to take predetermined action in response to the abnormality.    
   
   
       29 . The method of  claim 28  further including using said computer processing means to compute at least one degree of abnormality, wherein the or each degree of abnormality is a weighted function of one or more ratios and evaluating the degree of abnormality as one of said one or more ratios.  
   
   
       30 . The method of  claim 28  wherein the step of monitoring for a network traffic abnormality includes the step of monitoring for a denial of service attack.  
   
   
       31 . Apparatus for monitoring network traffic for a traffic profile abnormality, the apparatus including historical traffic data gathering means to provide at least one selected normal traffic parameter, observing means for observing the current traffic data relating to the selected parameter to provide at least one current traffic parameter, and evaluating means to evaluate a deviation between the normal traffic profile parameter and the current traffic profile parameter against a threshold to determine whether a traffic abnormality exists.  
   
   
       32 . Apparatus as claimed in  claim 31  wherein the selected parameter includes a plurality of parameters.  
   
   
       33 . Apparatus as claimed in  claim 32  wherein the evaluating means evaluates a-weighted sum of the deviations.  
   
   
       34 . A method of monitoring network traffic for a traffic profile abnormality, the method including the steps of gathering traffic data to provide at least one selected normal traffic parameter, observing the current traffic data relating to the selected parameter to provide at least one current traffic parameter, and evaluating a deviation between the normal traffic profile parameter and the current traffic profile parameter against a threshold to determine whether a traffic abnormality exists.  
   
   
       35 . A method as claimed In  claim 34  including the step of selecting a plurality of parameters.  
   
   
       36 . A method as claimed in  claim 35  including the step of evaluating a weighted sum of the deviations.  
   
   
       37 . Any novel feature or combination of features disclosed herein.

Join the waitlist — get patent alerts

Track US2005125195A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.